Hawt Hawtio vulnerabilities

8 known vulnerabilities affecting hawt/hawtio.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH4MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2023-33544MEDIUMCVSS 5.5v2.17.22023-06-01
CVE-2023-33544 [MEDIUM] CWE-22 CVE-2023-33544: hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which ca hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after decompression being stored in any location, even leading to file overwrite.
nvd
CVE-2019-9827CRITICALCVSS 9.8≤ 2.5.02019-07-03
CVE-2019-9827 [CRITICAL] CWE-918 CVE-2019-9827: Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP reque Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.
nvd
CVE-2017-2589CRITICALCVSS 9.0v1.4.02018-07-26
CVE-2017-2589 [CRITICAL] CWE-285 CVE-2017-2589: It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests wi It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.
nvd
CVE-2017-2617HIGHCVSS 7.8fixed in 1.5.52018-05-22
CVE-2017-2617 [HIGH] CWE-20 CVE-2017-2617: hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker coul hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.
nvd
CVE-2017-2594HIGHCVSS 7.5≤ 1.4.682018-05-08
CVE-2017-2594 [HIGH] CWE-209 CVE-2017-2594: hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a pat hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undisclosed information from within hawtio's root.
nvd
CVE-2014-0121CRITICALCVSS 9.8≤ 1.2.22017-12-29
CVE-2014-0121 [CRITICAL] CWE-287 CVE-2014-0121: The admin terminal in Hawt.io does not require authentication, which allows remote attackers to exec The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.
nvd
CVE-2014-0120HIGHCVSS 8.8≤ 1.2.22017-12-29
CVE-2014-0120 [HIGH] CWE-352 CVE-2014-0120: Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attac Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."
nvd
CVE-2017-7556HIGHCVSS 8.8v1.5.32017-08-17
CVE-2017-7556 [HIGH] CWE-352 CVE-2017-7556: Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attac Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website containing a malicious script which can be submitted to hawtio server on behalf of the user.
nvd